GMASO: A Graph-based Multi-Agent Security Optimizer for Threat-Specific Countermeasure Selection in Mission-Critical Systems

Document Type : Research Article

Authors

1 Department of Management, Science and Technology, Amirkabir University of Technology, Tehran, Iran

2 Department of Industrial Engineering, Tarbiat Modares University, Tehran, Iran

3 Department of Computer Engineering, Amirkabir University of Technology, Tehran, Iran

10.22042/isecure.2026.557565.1270
Abstract
Existing cybersecurity frameworks suffer from static threat assessment, inadequate modeling of system dependencies, oversimplified risk propagation, and inflexible countermeasure selection. This study presents a data-driven, multi-agent decision-support framework that optimizes countermeasure selection under operational constraints. The approach employs a dynamic graph structure representing relationships among missions, tasks, assets, threats, vulnerabilities, and countermeasures, with weighted dependencies across confidentiality, integrity, and availability dimensions. The framework comprises a modular architecture of ten specialized agents—namely the Main (serving as the Environment Controller agent), Node, Edge, Mission, Task, Asset, Threat, Vulnerability, Countermeasure, and Mapping Agents—organized into four functional categories (Control, Structural, Mission-Centric, and Security-Focused). These agents collaboratively operate through four sequential phases: (1) Data Gathering and Graph Construction, (2) Weight Propagation and Risk Assessment, (3) Multi-Criteria Optimization, and (4) Implementation and Reassessment. Experimental results demonstrate substantial improvements in risk mitigation efficiency and resource allocation compared to conventional approaches, enabling organizations to dynamically align security investments with evolving threats, mission priorities, and budget constraints while maintaining operational continuity.

Keywords


[1] Sajed Yousefi Mashhour, Motahareh Dehghan, Babak Sadeghian, and Alireza Hashemi Golpayegani. Mission-centric countermeasure selection in cybersecurity situation awareness systems. ISeCure, 2026. .
[2] V. Viduto, C. Maple, W. Huang, and D. LópezPeréz. A novel risk assessment and optimisation model for a multi-objective network securitycountermeasureselectionproblem. Decision Support Systems, 2012.
[3] I. Kotenko and E. Doynikova. Dynamical calculation of security metrics for countermeasure selection in computer networks. In 2016 24th Euromicro International Conference on Parallel, Distributed, and Network-Based Processing (PDP), 2016.
[4] A. Shameli-Sendi and M. Dagenais. Orcef: Online response cost evaluation framework for intrusion response system. Journal of Network and Computer Applications, 2015.
[5] P. Nespoli, D. Papamartzivanos, F. Gómez Mármol, and G. Kambourakis. Optimal countermeasures selection against cyber attacks: A comprehensive survey on reaction frameworks. IEEE Communications Surveys & Tutorials, 2018.
[6] U. Tariq, I. Ahmed, A. K. Bashir, and K. Shaukat. A critical cybersecurity analysis and futurere search directions for the internet of things: A comprehensive review. Sensors, 2023.
[7] A. Roy, D. S. Kim, and K. S. Trivedi. Scalable optimal countermeasure selection using implicit enumeration on attack countermeasure trees. In IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2012), 2012.
[8] Kjell Hausken, Jonathan W. Welburn, and Jun Zhuang. A review of attacker–defender games and cyber security. Games, 2024.
[9] S.Wang,Z.Zhang,andY.Kadobayashi.Exploring attack graph for cost-benefit security hardening: A probabilistic approach. Computers & Security, 2013.
[10] R. Dewri, I. Ray, N. Poolsappasit, and D. Whitley. Optimal security hardening on attack tree models of networks: a cost-benefit analysis. International Journal of Information Security, 2012.
[11] G.Gonzalez-Granadillo,J.Garcia-Alfaro,E.Alvarez, M. El-Barbori, and H. Debar. Selecting optimal countermeasures for attacks against critical systems using the attack volume model and the rori index. Computers & Electrical Engineering, 2015.
[12] Abdelkarim Ait Temghart, Mbarek Marwan, and Mohamed Baslam. Stackelberg security game for optimizing cybersecurity decisions in cloud computing. Security and Communication Networks.
[13] A. Shameli-Sendi, H. Louafi, W. He, and M. Cheriet. Dynamic optimal countermeasure selection for intrusion response system. IEEE Transactions on Dependable and Secure Computing, 2018.
[14] F. Ö. Sönmez and B. G. Kılıç. A decision support system for optimal selection of enterprise information security preventative actions. IEEE Transactions on Network and Service Management, 2021.
[15] Diksha Goel, Kristen Moore, Mingyu Guo, Derui Wang, Minjune Kim, and Seyit Camtepe. Optimizing cyber defense in dynamic active directories through reinforcement learning, 2024. Accepted at ESORICS 2024.
[16] F. Li, Y. Li, S. Leng, Y. Guo, K. Geng, Z. Wang, and L. Fang. Dynamic countermeasures selection for multi-path attacks. Computers & Security, 2020.
[17] J. Watters, S. Morrissey, D. Bodeau, and S. C. Powers. The risk-to-mission assessment process: A sensitivity analysis and an extension to treat confidentiality issues. Technical report, 2009.